← QORVILO OS

Security & Incident Response Policy

Last updated: September 24, 2026

Our safeguards

  • Store access tokens encrypted at rest (AES-256-GCM); never sent to the browser.
  • All traffic over HTTPS/TLS.
  • Each merchant's data isolated at the database level.
  • Incoming store webhooks verified by signature before processing.
  • Sensitive actions recorded in an audit log.

Incident response

AI Chat Hub follows this process for any suspected security incident or data breach:

  • Detect & report — incidents are identified through monitoring, audit logs or reports to qorviloos@gmail.com.
  • Assess — confirm the incident, its scope, and which merchants and data are affected.
  • Contain — revoke or rotate affected credentials, disable affected integrations, and block the source.
  • Notify — inform affected merchants, and Shopify where Shopify data is involved, without undue delay and within 72 hours of confirmation; notify regulators where the law requires.
  • Recover — restore service and verify data integrity.
  • Review — document the root cause and improvements, and update this policy.

Report a vulnerability

Email qorviloos@gmail.com.